Data Processing Agreement (DPA)
Effective from March 26, 2026
§1 Parties
Controller (Client) – the entity using the Service.
Processor (Service Provider) – R4_TECH Rafał Jurek, Al. Ks.K.S. Wyszyńskiego 76/7, 94-047 Łódź, Poland. VAT ID: PL7282787249.
§2 Subject Matter
The Controller entrusts the Processor with processing personal data in connection with the use of the Service. Processing takes place solely for the purpose of providing the Service.
§3 Categories of Data
Processed data may include:
• identification data,
• contact data,
• accounting data (KSeF),
• system logs.
§4 Nature of Processing
• storing data,
• organising data,
• making data available to the user,
• processing in an information system.
§5 Processor Obligations
The Processor undertakes to:
• process data in compliance with the GDPR,
• ensure confidentiality,
• apply appropriate security measures,
• not use the data for its own purposes.
§6 Sub-processors
The Processor uses the following sub-processors:
• OVH
• Stripe
• Cloudflare
• Google
• Zoho Corporation Pvt. Ltd.
The Controller consents to their use.
§7 International Transfers
Data may be transferred outside the EEA in accordance with the GDPR (Standard Contractual Clauses).
§8 Security
The Processor applies: access controls, encrypted transmission (HTTPS), and infrastructure security measures.
§9 Data Breaches
The Processor undertakes to notify the Controller of any data breach without undue delay.
§10 Duration
This Agreement remains in force for the duration of the Service.
§11 Data Deletion
Upon termination of the Service, data may be deleted or returned to the Controller.
§12 Audit
The Controller has the right to audit the Processor's compliance with this Agreement.